3 unchanged sentences
We take cybersecurity seriously and have developed a cybersecurity program that consists of processes, policies, and controls for assessing, identifying, managing, and responding to material risks from these threats.
−Removed: Our cybersecurity program is integrated within our broader risk management function that identifies, monitors, and mitigates business, operational, financial, and legal risks.
+Added: Our cybersecurity program is
+Added: integrated within our broader risk management function that identifies, monitors, and mitigates business, operational, financial, and legal risks.
Our processes include controls that our Director of Information Technology and our Technology Department implement, which seek to protect our company, assets, information, and our employees from cyber threats, and provide regular education for our employees.
12 unchanged sentences
We use a third party to perform annual security assessments .
−Removed: This includes both external penetration testing and internal vulnerability testing, as well as a security program maturity assessment based on the NIST framework (National Institute of Standards and Technology).
+Added: This includes both external penetration testing and internal vulnerability testing, as well as a security program maturity assessment based on the NIST framework.
External testing consists of scanning all our public IP addresses for open ports and determining if any device or service on those ports have known vulnerabilities.
9 unchanged sentences
Our Director of Information Technology along with our management team, which includes our Chief Executive Officer, Chief Financial Officer, and General Counsel, will coordinate to execute the appropriate response plan and will also investigate any issue to determine whether an incident is material, requiring disclosure to shareholders in SEC filings.
−Removed: Our Board of Directors and our Audit Committee also receive prompt and timely information regarding any cybersecurity risk and ongoing updates regarding any such risk.
−Removed: Our Director of Information Technology has thirty years of experience in information technology, which includes the past nineteen years managing Intrepid's information technology infrastructure, business applications, compliance programs, and cybersecurity systems.
+Added: Our Board of Directors and our Audit
+Added: Committee also receive prompt and timely information regarding any cybersecurity risk and ongoing updates regarding any such risk.
+Added: Our Director of Information Technology has over thirty years of experience in information technology, which includes the past twenty years managing Intrepid's information technology infrastructure, business applications, compliance programs, and cybersecurity systems.
Although our management team and Audit Committee receive information regarding our cybersecurity program and help assess our strategy based on their knowledge of our business and industry, no member of the management team or Audit Committee has technology or cybersecurity expertise.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.